{# SPDX-License-Identifier: Apache-2.0 -#}
{% extends "email/_base/body.html" %}
{% block content %}
  <p>
    PyPI user <strong>{{ username }}</strong> has added a new trusted
    publisher to a project (<strong>{{ project_name }}</strong>) that you manage.
    Trusted publishers act as trusted users and can create project releases
    automatically.
  </p>
  <p>
    Publisher information:
    <ul>
      <li>Publisher name: {{ publisher.publisher_name }}</li>
      {% if publisher.publisher_name == "GitHub" %}
        <li>Workflow: {{ publisher }}</li>
        <li>Owner: {{ publisher.repository_owner }}</li>
        <li>Repository: {{ publisher.repository_name }}</li>
        {% if publisher.environment %}<li>Environment: {{ publisher.environment }}</li>{% endif %}
      {% elif publisher.publisher_name == "Google" %}
        <li>Email: {{ publisher.email }}</li>
        {% if publisher.sub %}<li>Subject: {{ publisher.sub }}</li>{% endif %}
      {% elif publisher.publisher_name == "ActiveState" %}
        <li>ActiveState Project URL: {{ publisher.publisher_url }}</li>
        <li>Organization: {{ publisher.organization }}</li>
        <li>ActiveState Project name: {{ publisher.activestate_project_name }}</li>
        <li>Actor: {{ publisher.actor }}</li>
      {% endif %}
    </ul>
  </p>
  <p>
    If you did not make this change and you think it was made maliciously, you can
    remove it from the project via the "Publishing" tab on the project's page.
  </p>
  <p>
    If you are unable to revert the change and need to do so, you can email
    <a href="mailto:admin@pypi.org">admin@pypi.org</a> to communicate with the PyPI
    administrators.
  </p>
{% endblock %}
